bug 642319
[phpmyadmin/crack.git] / tbl_addfield.php3
blob3d8c8e7ec8acfb5896fad206bb82ead178a17a8c
1 <?php
2 /* $Id$ */
3 // vim: expandtab sw=4 ts=4 sts=4:
6 /**
7 * Get some core libraries
8 */
9 require('./libraries/grab_globals.lib.php3');
10 if (isset($submit)) {
11 $js_to_run = 'functions.js';
13 require('./header.inc.php3');
16 /**
17 * Defines the url to return to in case of error in a sql statement
19 $err_url = 'tbl_properties.php3'
20 . '?lang=' . $lang
21 . '&amp;convcharset=' . $convcharset
22 . '&amp;server=' . $server
23 . '&amp;db=' . urlencode($db)
24 . '&amp;table=' . urlencode($table);
27 /**
28 * The form used to define the field to add has been submitted
30 if (isset($submit)) {
31 $query = '';
33 // Transforms the radio button field_key into 3 arrays
34 $field_cnt = count($field_name);
35 for ($i = 0; $i < $field_cnt; ++$i) {
36 if (isset(${'field_key_' . $i})) {
37 if (${'field_key_' . $i} == 'primary_' . $i) {
38 $field_primary[] = $i;
40 if (${'field_key_' . $i} == 'index_' . $i) {
41 $field_index[] = $i;
43 if (${'field_key_' . $i} == 'unique_' . $i) {
44 $field_unique[] = $i;
46 } // end if
47 } // end for
48 // Builds the field creation statement and alters the table
49 for ($i = 0; $i < $field_cnt; ++$i) {
50 if (get_magic_quotes_gpc()) {
51 $field_name[$i] = stripslashes($field_name[$i]);
53 if (PMA_MYSQL_INT_VERSION < 32306) {
54 PMA_checkReservedWords($field_name[$i], $err_url);
57 $query .= PMA_backquote($field_name[$i]) . ' ' . $field_type[$i];
58 if ($field_length[$i] != ''
59 && !eregi('^(DATE|DATETIME|TIME|TINYBLOB|TINYTEXT|BLOB|TEXT|MEDIUMBLOB|MEDIUMTEXT|LONGBLOB|LONGTEXT)$', $field_type[$i])) {
60 if (get_magic_quotes_gpc()) {
61 $query .= '(' . stripslashes($field_length[$i]) . ')';
62 } else {
63 $query .= '(' . $field_length[$i] . ')';
66 if ($field_attribute[$i] != '') {
67 $query .= ' ' . $field_attribute[$i];
69 if ($field_default[$i] != '') {
70 if (strtoupper($field_default[$i]) == 'NULL') {
71 $query .= ' DEFAULT NULL';
72 } else if (get_magic_quotes_gpc()) {
73 $query .= ' DEFAULT \'' . PMA_sqlAddslashes(stripslashes($field_default[$i])) . '\'';
74 } else {
75 $query .= ' DEFAULT \'' . PMA_sqlAddslashes($field_default[$i]) . '\'';
78 if ($field_null[$i] != '') {
79 $query .= ' ' . $field_null[$i];
81 if ($field_extra[$i] != '') {
82 $query .= ' ' . $field_extra[$i];
83 // An auto_increment field must be use as a primary key
84 if ($field_extra[$i] == 'AUTO_INCREMENT' && isset($field_primary)) {
85 $primary_cnt = count($field_primary);
86 for ($j = 0; $j < $primary_cnt && $field_primary[$j] != $i; $j++) {
87 // void
88 } // end for
89 if ($field_primary[$j] == $i) {
90 $query .= ' PRIMARY KEY';
91 unset($field_primary[$j]);
92 } // end if
93 } // end if (auto_increment)
96 if ($after_field != '--end--') {
97 // Only the first field can be added somewhere else than at the end
98 if ($i == 0) {
99 if ($after_field == '--first--') {
100 $query .= ' FIRST';
101 } else {
102 if (get_magic_quotes_gpc()) {
103 $query .= ' AFTER ' . PMA_backquote(stripslashes(urldecode($after_field)));
104 } else {
105 $query .= ' AFTER ' . PMA_backquote(urldecode($after_field));
108 } else {
109 if (get_magic_quotes_gpc()) {
110 $query .= ' AFTER ' . PMA_backquote(stripslashes($field_name[$i-1]));
111 } else {
112 $query .= ' AFTER ' . PMA_backquote($field_name[$i-1]);
116 $query .= ', ADD ';
117 } // end for
118 $query = ereg_replace(', ADD $', '', $query);
120 // To allow replication, we first select the db to use and then run queries
121 // on this db.
122 $sql_query = 'USE ' . PMA_backquote($db);
123 $result = PMA_mysql_query($sql_query) or PMA_mysqlDie('', '', '', $err_url);
124 $sql_query = 'ALTER TABLE ' . PMA_backquote($table) . ' ADD ' . $query;
125 $result = PMA_mysql_query($sql_query) or PMA_mysqlDie('', '', '', $err_url);
126 $sql_query_cpy = $sql_query . ';';
128 // Builds the primary keys statements and updates the table
129 $primary = '';
130 if (isset($field_primary)) {
131 $primary_cnt = count($field_primary);
132 for ($i = 0; $i < $primary_cnt; $i++) {
133 $j = $field_primary[$i];
134 $primary .= PMA_backquote($field_name[$j]) . ', ';
135 } // end for
136 $primary = ereg_replace(', $', '', $primary);
137 if (!empty($primary)) {
138 $sql_query = 'ALTER TABLE ' . PMA_backquote($table) . ' ADD PRIMARY KEY (' . $primary . ')';
139 $result = PMA_mysql_query($sql_query) or PMA_mysqlDie('', '', '', $err_url);
140 $sql_query_cpy .= "\n" . $sql_query . ';';
142 } // end if
144 // Builds the indexes statements and updates the table
145 $index = '';
146 if (isset($field_index)) {
147 $index_cnt = count($field_index);
148 for ($i = 0; $i < $index_cnt; $i++) {
149 $j = $field_index[$i];
150 $index .= PMA_backquote($field_name[$j]) . ', ';
151 } // end for
152 $index = ereg_replace(', $', '', $index);
153 if (!empty($index)) {
154 $sql_query = 'ALTER TABLE ' . PMA_backquote($table) . ' ADD INDEX (' . $index . ')';
155 $result = PMA_mysql_query($sql_query) or PMA_mysqlDie('', '', '', $err_url);
156 $sql_query_cpy .= "\n" . $sql_query . ';';
158 } // end if
160 // Builds the uniques statements and updates the table
161 $unique = '';
162 if (isset($field_unique)) {
163 $unique_cnt = count($field_unique);
164 for ($i = 0; $i < $unique_cnt; $i++) {
165 $j = $field_unique[$i];
166 $unique .= PMA_backquote($field_name[$j]) . ', ';
167 } // end for
168 $unique = ereg_replace(', $', '', $unique);
169 if (!empty($unique)) {
170 $sql_query = 'ALTER TABLE ' . PMA_backquote($table) . ' ADD UNIQUE (' . $unique . ')';
171 $result = PMA_mysql_query($sql_query) or PMA_mysqlDie('', '', '', $err_url);
172 $sql_query_cpy .= "\n" . $sql_query . ';';
174 } // end if
177 // Builds the fulltext statements and updates the table
178 $fulltext = '';
179 if (PMA_MYSQL_INT_VERSION >= 32323 && isset($field_fulltext)) {
180 $fulltext_cnt = count($field_fulltext);
181 for ($i = 0; $i < $fulltext_cnt; $i++) {
182 $j = $field_fulltext[$i];
183 $fulltext .= PMA_backquote($field_name[$j]) . ', ';
184 } // end for
185 $fulltext = ereg_replace(', $', '', $fulltext);
186 if (!empty($fulltext)) {
187 $sql_query = 'ALTER TABLE ' . PMA_backquote($table) . ' ADD FULLTEXT (' . $fulltext . ')';
188 $result = PMA_mysql_query($sql_query) or PMA_mysqlDie('', '', '', $err_url);
189 $sql_query_cpy .= "\n" . $sql_query . ';';
191 } // end if
193 // Go back to the structure sub-page
194 $sql_query = $sql_query_cpy;
195 unset($sql_query_cpy);
196 $message = $strTable . ' ' . htmlspecialchars($table) . ' ' . $strHasBeenAltered;
197 include('./tbl_properties_structure.php3');
198 exit();
199 } // end do alter table
202 * Displays the form used to define the new field
204 else{
205 $action = 'tbl_addfield.php3';
206 include('./tbl_properties.inc.php3');
208 // Diplays the footer
209 echo "\n";
210 include('./footer.inc.php3');